Nigri Shluchim Online School · EaseInTech

Workspace safeguards — status

Where every protection stands right now, in plain terms. Each item names what it does, and what changes for students once it is in place.

Updated 20 August 2026
Live — in place and working In progress — being built or resolved Planned — designed, not yet started Waiting on the school — needs an input from you

Google Drive & Docs

Keeping student documents supervised, and stopping documents from becoming private, unwatched spaces.

7 Live 1 Planned

File creation & upload disabled — Grades 1–2

Drive & Docs settings · both divisions
Live

The youngest students cannot create documents or upload files, so they have no Drive of their own. They can still open and work in documents a teacher shares with them.

BeforeGrades 1–2 could create and upload freely, accumulating unmanaged files and gaining a sharing surface.
NowThey hold no files of their own — nothing to accumulate, nothing to share — while still working inside what teachers give them.

Student-to-student sharing blocked

Drive Trust Rules · server-side
Live

Students cannot share documents with each other, or receive shares from each other. This is enforced on Google's servers, so it holds on any device or browser — a phone, a home laptop, anywhere.

BeforeA student could share a document with classmates and turn it into an unsupervised shared space.
NowStudent-to-student sharing is refused at the server, everywhere, with nothing to bypass in the browser.

Re-share prevention on teacher documents

Automated sharing lock · verified
Live

The moment a student is given edit access to a teacher-owned document, their ability to invite anyone else is removed — automatically, and within seconds.

BeforeGoogle's default lets an edit-access student re-share the document with anyone, pulling outsiders into a teacher's file.
NowThat ability is stripped the instant it appears. A student who tries to add someone triggers an approval request to the teacher instead of a silent share.

Abandoned-document lockdown

Scheduled automation
Live

Teacher-owned documents with two or more student editors that the teacher has not opened or edited for a set period automatically have those students dropped to view-only.

BeforeA shared document a teacher forgets stays fully editable and can quietly become an unsupervised hangout.
NowForgotten collaborative documents close themselves. A teacher simply re-opening or re-sharing reinstates access — no request needed.

SafeDoc configuration changes

SafeDoc · six organizational-unit configurations
Live

Delivering the SafeDoc setting changes the principals requested, and rolling out SafeDoc's own newly released updates, across all six student configurations.

BeforeStudents still had the Share button. And documents owned by teachers in the shluchimonlineschool.com domain sit outside the reach of the new Lock and Hunter tools — students could still open them, unprotected.
NowThe Share button is removed; shluchimonlineschool.com is removed from the allow list, so students can no longer open those unprotected documents; and the other requested changes are applied — across all six configurations.

Managed-session access gate — Drive & Chat

Context-Aware Access + Endpoint Verification · server-side
Live

Google Drive and Google Chat are reachable only from a managed school profile. From a guest window, a browser that isn't signed-in Chrome, or a browser signed in with a personal Gmail account, access is refused outright.

BeforeSchool Drive and Chat could be opened from any browser, profile, or device.
NowBlocked immediately outside the managed school profile — enforced at Google's servers, not by a browser add-on, so there is nothing to bypass.

This is the protection that makes the others hold. It uses Google's Endpoint Verification, deployed to student devices, to recognize the managed profile; the block itself is server-side, and was tested and rolled out across the school.

Per-assignment collaboration

Google Classroom add-on
Planned

A controlled way for a teacher to open collaboration for one assignment's documents only — for exactly the students who need it, for as long as they need it — instead of collaboration being all-or-nothing.

BeforeCollaboration is either fully open, which is risky, or fully closed, which limits real classwork.
AfterA teacher opens it per assignment, and it closes itself afterward.

Student Drive cleanout — Boys division

Drive sweep + archive
Live

A full cleanout of every boys student's Drive — files moved into a per-student archive, and accumulated junk, stray uploads, shared-with-me items and shortcuts cleared out — including files that were held in the previous tenant.

BeforeYears of clutter, old assignments, stray uploads, and shared-with-me connections across every student account.
NowAccounts cleared to a clean baseline, with prior files preserved in an archive — and the creation limits keep clutter from rebuilding.

Status: complete. A small number of shared-with-me or shortcut connections may linger after a thorough pass. (The Girls-division clearance was withdrawn at the school's request.)

Google Chat

Controlling who students may message, keeping conversations supervised, and giving leadership a graduated way to respond.

3 Live 2 In progress 5 Planned 2 Waiting

Chat availability by grade band

Chat service settings
Live

Chat is switched on only for the grades each division chose — Boys 5–8 and Girls 6–8 — and off for everyone below that.

BeforeChat was broadly available across grades.
NowAvailable only where each principal chose to allow it.

Managed-session access gate — Chat

Context-Aware Access · server-side
Live

The same server-side gate applied to Drive also covers Google Chat: it is reachable only from a managed school profile. From a guest window, a non-Chrome browser, or a browser signed in with a personal Gmail account, Chat is refused.

BeforeChat could be opened from any browser, profile, or device.
NowBlocked outside the managed school profile — enforced at Google's servers, so there is nothing to bypass.

Consequence level 1 — restrict initiation

Chat restriction group
In progress

A student placed in this group can no longer start new messages, group messages, or spaces. Existing conversations continue, so it is a measured first step rather than a full shutoff.

BeforeNo graduated way to respond to chat misuse — only on or off.
TargetA first-tier consequence that stops new activity without cutting the student off entirely.

Status: the restriction group is created in the Admin console and can be applied by hand today. The mechanism that moves students in and out automatically is part of the chat system, and is not yet built.

Consequence level 2 — chat off

Organizational Unit
In progress

A student moved into this sub-group has chat fully disabled, while keeping every other policy of their grade unchanged.

BeforeRemoving chat meant a manual, all-or-nothing change.
TargetA second-tier consequence — full chat removal — applied on demand.

Status: the sub-group with chat disabled is created. The mechanism that moves a student into it is not yet built.

Space creation blocked — interim measure

SafeDoc chat configuration · temporary
Live

For now, students are blocked from creating chat spaces at all. This holds the line until the capture-and-supervise system below is in place — at which point students can create spaces again and each one is automatically brought under supervision.

BeforeStudents could create chat spaces freely.
NowSpace creation is switched off for students — a deliberate temporary hold, to be lifted once full supervision replaces it.

Delivered as a SafeDoc chat-configuration update across all configurations, per the principals' decisions.

Space governance — capture & supervise

Chat automation
Planned

When a student creates a chat space, it is automatically brought under supervision — converted to a monitored space, the student's ownership removed, and every member they try to add screened against the messaging rules.

BeforeStudents create private chat spaces with no supervision — and as the creator, a student holds owner power over the space, including removing other students from it. That power becomes a tool for exclusion.
AfterAny space a student creates is captured and supervised the moment it appears — the student's owner power is removed, so no one can quietly control or exclude classmates, and every added member is screened.

Messaging boundary enforcement

Membership screening
Planned

Boys may message within their own grade; Girls within their own division. Enforced by controlling who is allowed into a conversation in the first place.

BeforeStudents could message across the boundaries the principals set.
AfterOnly permitted participants can be in a conversation, by construction.

Direct-message screening

Chat automation
Planned

One-to-one and small-group messages between students who are not permitted to talk are detected and removed — including a group quietly spun out of a direct message.

BeforeDirect messages are the one place the boundary can't be enforced at the door.
AfterDisallowed direct exchanges are caught and cleared.

Inappropriate-language detection

Data Loss Prevention (DLP) · custom rules from real data
Waiting on the school

Messages are screened by detection rules built specifically for this school. The rules are derived by analyzing last year's chats and the incidents that actually came up — turned into detection patterns tuned to catch bullying and inappropriate language as it really appears here, in English and in Hebrew or Yiddish. Tiered, so a severe match blocks and notifies, a milder one warns, and a watch list quietly logs.

BeforeNo automated screening of chat language, and nothing learned from the incidents that already happened.
AfterLive screening built from this school's own history — catching the patterns that actually occurred, not a generic word list.

Needs from the school: authorization to analyze last year's group conversations and incident history, so the detection is built from real data rather than guesswork.

Scheduled chat availability

Context-Aware Access
Waiting on the school

Chat becomes reachable only during permitted hours, set per class and per timezone, so it is not open during lessons.

BeforeChat is available at any hour of the day.
AfterAvailable only inside the windows each class allows.

Needs from the school: bell times entered into the scheduling screens — per class, with each class's timezone. The rules are generated from that data directly.

Incident dashboard & consequence workflow

Leadership tool
Planned

A leadership view of flagged incidents — with the message, the surrounding context, and one-click ways to apply or reverse a consequence, all kept on the record.

BeforeDetection with no central place to review it or act on it.
AfterA dashboard that turns detection into a decision, with a full audit trail.

Context & behaviour analysis

Optional AI layer
Planned

An optional layer that reads the surrounding conversation to judge whether a flag is a genuine incident, and recommends a response — with a person always making the final call.

BeforeEvery flag is judged from the single message alone.
AfterFlags come with context and a recommendation, so review is faster and fairer.